URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 78 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand YouTube scan id 26c4564a duration 28.53s signals 1 failing / 12
Risk score 0.03
3 / 100 · Low risk
Tags
https :// youtube . com /shorts/e1QmUns3JV8 ? si=jRiv7QLUyW68Vjq4
flagged registered domain path protocol / query
URL hxxps://youtube[.]com/shorts/e1QmUns3JV8?si=jRiv7QLUyW68Vjq4
Host youtube[.]com
Brand YouTube
Screenshot https://cdn.zerophish.ai/f440a6e3-9168-4650-8cb6-07d55ed28eb2.jpg
Scan ID 26c4564a-677b-48ad-8368-49eadc3a6cdc
395 d ago
REVIEW www.youtube.com safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to YouTube
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
Y
YouTube
100%
Host youtube.com
Registered domain youtube.com
Scheme https
Content length 1649769 B
HTTP 200 · text/html
JARM 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651
Redirect hops 4
Initial scan heuristic + LLM

Assessment (YouTube Shorts page)

What the page appears to be

This page is presenting a standard YouTube Shorts experience (video header, navigation like Home / Shorts / Subscriptions, and account entry). The OCR text includes typical YouTube UI such as “Skip navigation”, “Sign in to like videos, comment, and subscribe.”, and footer items like “TermsPrivacyPolicy & Safety” and “© 2026 Google LLC.”

Suspicious elements found (phishing signals)

None of the commonly used phishing patterns are present in the provided HTML/OCR:

  • No credential-harvesting form visible in the supplied content. The page shows sign-in links pointing to Google’s accounts system, not a custom login form.
  • No fake security warnings / urgency cues (e.g., “your account will be closed”) were observed.
  • No mismatched branding: the content and navigation clearly align with YouTube.
  • No suspicious redirects/domains are evident in the snippet. The sign-in destination uses accounts.google.com with a continue parameter back to a youtube.com/shorts URL.

Concrete relevant details from the HTML:

  • The login link is: https://accounts.google.com/ServiceLogin?service=youtube...&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin...&next=https%253A%252F%252Fwww.youtube.com%252Fshorts%252Fe1QmUns3JV8%253F...
  • The page title shown in HTML is: “… - YouTube”, and the OCR footer matches Google/YouTube standard text.

Brand and URL relationship

  • Identified brand: YouTube
  • URL domain: youtube.com (matches YouTube’s real domain)
  • The sign-in flow goes through accounts.google.com, which is expected for YouTube authentication.

Verdict

Legitimate: The page content and linked authentication endpoints match official YouTube/Google behavior, and there are no observed phishing-specific UI elements (no credential form impersonation, no fake warnings, no suspicious brand mismatch).